CCI-005008
CCI-005008 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - [SI-12(03)_ODP[01]; techniques used to dispose of information following the retention period are defined] are used to dispose of information following the retention period. - [SI-12(03)_ODP[02]; techniques used to destroy information following the retention period are defined] are used to destroy information following the retention period. - [SI-12(03)_ODP[03]; techniques used to erase information following the retention period are defined] are used to erase information following the retention period.
Validation Procedures
Examine: [SELECT FROM: System and information integrity policy; system and information integrity procedures; personally identifiable information processing policy; personally identifiable information processing procedures; records retention and disposition policy; records retention and disposition procedures; laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to information disposal; media protection policy; media protection procedures; system audit records; audit findings; information disposal records; system security plan; privacy plan; privacy impact assessment; privacy risk assessment documentation; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with information and records management, retention, and disposition responsibilities; organizational personnel with information security and privacy responsibilities; network administrators]. Test: [SELECT FROM: Organizational processes for information disposition; automated mechanisms supporting and/or implementing information disposition].